We've Completed a DPIA... Is That It?

We've Completed a DPIA... Is That It?

A helpful guide

💭 Ask yourself...

"If this project changed tomorrow, would our DPIA still be accurate?"

If the answer is no...

It's time to review it.

 

Short answer

A Data Protection Impact Assessment (DPIA) shouldn't be completed, filed away and forgotten.

It should evolve alongside your project.

As your processing changes, your understanding of the risks changes too.

A good DPIA tells the story of how privacy risks were identified, considered, challenged and managed throughout the life of a project—not just on the day it was approved.

 

Why is this important?

Many organisations complete a DPIA because they know it's required.

Unfortunately, some DPIAs become little more than a snapshot in time.

The project changes.

New technology is introduced.

New suppliers are appointed.

The scope expands.

But the DPIA stays exactly the same.

Over time, the document no longer reflects reality.

A DPIA only adds value if it evolves alongside the processing it is assessing.

A DPIA isn't there to stop projects. It's there to help projects succeed safely.

 

A DPIA should have an owner

One of the biggest reasons DPIAs become outdated is that nobody is responsible for them.

Every DPIA should have a clearly identified owner who is responsible for:

  • keeping it under review; 
  • updating it when the project changes; 
  • ensuring agreed actions are completed; 
  • recording key decisions. 

Ownership creates accountability.

Without it, a DPIA can quickly become an historic document rather than a useful management tool.

 

The DPO's advice matters

Where a Data Protection Officer is appointed and involved, their advice should be recorded as part of the DPIA process.

Just as importantly, the organisation should record whether that advice was accepted or, if not, why a different decision was made.

This doesn't mean the DPO makes the business decision.

It means the organisation can demonstrate that independent privacy advice was sought and properly considered.

 

A DPIA should tell the story of a project

A good DPIA isn't simply a list of risks.

It should explain:

  • what the project is trying to achieve; 
  • why personal information is needed; 
  • what risks were identified; 
  • what mitigations were introduced; 
  • what decisions were made; 
  • who approved those decisions; 
  • when the DPIA was last reviewed. 

It should provide a clear record of how privacy was considered throughout the life of the project.

 

Practical steps

  1. Identify who owns the DPIA. 
  2. Record the purpose and scope of the project. 
  3. Involve the right people, including the DPO where appropriate. 
  4. Record decisions, actions and approvals. 
  5. Review the DPIA whenever the project changes. 
  6. Keep a record of when the DPIA was last reviewed and by whom. 

 

Common Misconceptions

"Once I've completed a DPIA, it's finished."

Not correct.

A DPIA should be reviewed whenever the processing changes or new risks emerge.

 

"The DPO signs off the DPIA."

Not necessarily.

The DPO provides independent advice. The organisation remains responsible for the final decision and should record how the DPO's advice was considered.

 

"A DPIA is just another compliance document."

Not at all.

A good DPIA supports better decision-making. It helps organisations identify risks early and build privacy into projects from the outset.

 

"Only the compliance team should be involved."

No.

The people designing, implementing and operating the project often have the best understanding of how personal information is used. A DPIA is strongest when it reflects input from across the organisation.

 

"If nothing has gone wrong, I don't need to review my DPIA."

Not necessarily.

Projects evolve. Systems change. Suppliers change. New risks emerge. Regular reviews help ensure the DPIA continues to reflect reality.

 

🤝 Need a little support?

A good DPIA isn't about predicting every possible risk—it's about demonstrating that privacy has been properly considered and that decisions have been made thoughtfully and transparently.

If you're starting a new project, reviewing an existing DPIA or simply want an independent view on whether your assessment still reflects the way your organisation works, we're happy to help.

Related Guidance:

Do My Data Protection Policies Actually Reflect My Business? 

How Do I Keep Track of All the Personal Data? 

Can I Just Rely on Legitimate Interests? 

Information icon

We need your consent to load the translations

We use a third-party service to translate the website content that may collect data about your activity. Please review the details in the privacy policy and accept the service to view the translations.